feat(07-01): add bcrypt, locale override, and validation rules

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-22 13:39:25 +02:00
parent bccd7f8f35
commit 8fcaff77cf
6 changed files with 95 additions and 15 deletions

27
bouncer/password.go Normal file
View File

@@ -0,0 +1,27 @@
package bouncer
import "golang.org/x/crypto/bcrypt"
// HashPassword returns a bcrypt hash of plain at the given cost.
func HashPassword(cost int, plain string) (string, error) {
b, err := bcrypt.GenerateFromPassword([]byte(plain), cost)
if err != nil {
return "", err
}
return string(b), nil
}
// CheckPassword reports whether plain matches hash. A malformed hash returns false.
func CheckPassword(hash, plain string) bool {
return bcrypt.CompareHashAndPassword([]byte(hash), []byte(plain)) == nil
}
// NeedsRehash reports whether hash was produced below configuredCost.
// A hash bcrypt cannot parse needs a rehash.
func NeedsRehash(hash string, configuredCost int) bool {
cost, err := bcrypt.Cost([]byte(hash))
if err != nil {
return true
}
return cost < configuredCost
}